VendorsIncsubforminatorall versions
Vulnerabilities

Incsub Forminator

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

20CVEs
CVE-2023-4596
Forminator <= 1.24.6 - Unauthenticated Arbitrary File Upload
Published 2023-08-30 · Modified
9.8EPSS 0.143
CVE-2025-6463
Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.44.2 - Unauthenticated Arbitrary File Deletion Triggered via Administrator Form Submission Deletion
Published 2025-07-02 · Analyzed
8.8EPSS 0.127
CVE-2025-6464
Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.44.2 - Unauthenticated PHP Object Injection (PHAR) Triggered via Administrator Form Submission Deletion
Published 2025-07-02 · Analyzed
8.8EPSS 0.005
CVE-2024-7389
Forminator <= 1.29.1 - HubSpot Developer API Key Sensitive Information Exposure
Published 2024-08-02 · Analyzed
7.5EPSS 0.007
CVE-2024-31077
Forminator prior to 1.29.3 contains a SQL injection vulnerability. If this vulnerability is exploited, a remote authenticated attacker with an administrative privilege may obtain and alter any information in the database and cause a denial-of-service (DoS) condition.
Published 2024-04-23 · Analyzed
7.2EPSS 0.304
CVE-2024-1794
Forminator <= 1.29.0 - Unauthenticated Stored Cross-Site Scripting via File Upload
Published 2024-04-09 · Modified
7.2EPSS 0.005
CVE-2024-29777
WordPress Forminator plugin <= 1.29.0 - Reflected Cross Site Scripting (XSS) vulnerability
Published 2024-03-27 · Modified
7.1EPSS 0.004
CVE-2021-36821
WordPress Forminator plugin <= 1.14.11 - Stored Cross-Site Scripting (XSS) vulnerability
Published 2023-03-16 · Modified
7.1EPSS 0.004
CVE-2023-6133
Forminator <= 1.27.0 - Authenticated (Administrator+) Arbitrary File Upload
Published 2023-11-15 · Modified
6.6EPSS 0.009
CVE-2019-9568
The "Forminator Contact Form, Poll & Quiz Builder" plugin before 1.6 for WordPress has SQL Injection via the wp-admin/admin.php?page=forminator-entries entry[] parameter if the attacker has the delete permission.
Published 2019-03-04 · Modified
6.5EPSS 0.016
CVE-2024-3053
Forminator – Contact Form, Payment Form & Custom Form Builder <= 1.29.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via forminator_form Shortcode
Published 2024-04-09 · Modified
6.4EPSS 0.004
CVE-2023-3134
Forminator < 1.24.4 - Reflected XSS
Published 2023-07-31 · Modified
6.1EPSS 0.041
CVE-2019-9567
The "Forminator Contact Form, Poll & Quiz Builder" plugin before 1.6 for WordPress has XSS via a custom input field of a poll.
Published 2019-03-04 · Modified
6.1EPSS 0.013
CVE-2024-45625
Cross-site scripting vulnerability exists in Forminator versions prior to 1.34.1. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who follows a crafted URL and accesses the webpage with the web form created by Forminator.
Published 2024-09-09 · Modified
6.1EPSS 0.004
CVE-2024-31857
Forminator prior to 1.15.4 contains a cross-site scripting vulnerability. If this vulnerability is exploited, a remote attacker may obtain user information etc. and alter the page contents on the user's web browser.
Published 2024-04-23 · Analyzed
5.4EPSS 0.006
CVE-2021-4417
Forminator – Contact Form, Payment Form & Custom Form Builder <= 1.13.4 - Cross-Site Request Forgery Bypass
Published 2023-07-12 · Modified
5.4EPSS 0.004
CVE-2024-28890
Forminator prior to 1.29.0 contains an unrestricted upload of file with dangerous type vulnerability. If this vulnerability is exploited, a remote attacker may obtain sensitive information by accessing files on the server, alter the site that uses the plugin, and cause a denial-of-service (DoS) condition.
Published 2024-04-23 · Analyzed
5.3EPSS 0.007
CVE-2021-24700
Forminator < 1.15.4 - Admin+ Stored Cross-Site Scripting
Published 2021-11-23 · Modified
4.8EPSS 0.006
CVE-2023-5119
Forminator and Forminator Pro < 1.27.0 - Admin+ Stored Cross-Site Scripting
Published 2023-11-20 · Modified
4.8EPSS 0.005
CVE-2023-2010
Forminator < 1.24.1 - Unauthenticated Race Condition on poll vote
Published 2023-07-04 · Modified
3.1EPSS 0.004